Privacy information
Privacy at TailTested UK
This page describes information flows shown in the current site implementation. Details the checkout does not establish are identified below rather than assumed.
Accounts and sign-in
Creating an account asks for your name, email address and password. Signing in asks for your email address and password. The site uses a database-backed Better Auth system for these account flows. After a successful sign-up or sign-in, the system issues a session cookie so the site can maintain your session.
The profile page displays your account name and email address. It lets you resend an email verification message when needed and sign out. The current profile page has no self-service profile editing or account deletion control.
Email verification
Sign-up requests email verification. The verification link is sent using the installed email module through the Polsia email proxy, and the authentication system keeps a verification record for that flow. The profile page also offers a way to request another verification email. The checkout does not identify the proxy’s downstream delivery provider or an email retention period.
Browser storage and optional analytics
When you choose a display theme, the theme control stores that choice in your browser's local storage under theme.
The site also contains an optional visitor beacon. If the deployment suppliesPOLSIA_ANALYTICS_SLUG, the browser creates a random identifier when needed and stores it in local storage as polsia_vid. Once per page load, it sends the configured slug and identifier to POLSIA_API_BASE_URL, which defaults in the app code to https://polsia.com. The checkout does not show whether analytics is enabled on the live deployment or how the platform uses or retains beacon data.
Contact form
The public /contact form asks for your name, email address and message. The app validates those fields and saves a submitted message in its database with a generated record ID and creation time.
After saving the message, the app tries to record the submission in the Polsia dashboard as a message from you, marked with the contact_form source. If the dashboard records nothing or that attempt fails, the app tries to email a notification to the company's configured inbox. These notification attempts do not undo a saved message or fail a successful submission. The checkout does not designate that inbox as a privacy-request address or describe a privacy request process.
Example demo
The directly reachable but unlinked /example demo accepts a name, submits it to the example API and displays the returned value in temporary page state. The API returns an empty list when read and uses a generated ID for submissions; its database write is commented out. The current demo therefore does not save the submitted name in the app database.
Retailer links
TailTested UK links to retailer websites and says retailers handle payment and fulfilment. There is no on-site purchase or payment form. Retailer destinations are separate sites with their own practices; the checkout does not establish what they collect or how they use it.
Details not documented here
The current checkout does not establish the following details. No answer is inferred from the site code:
- The legal operator or controller name, the applicable legal bases, or whether tailtested-uk@polsia.app is the designated privacy enquiry address.
- Retention and deletion periods or processes for accounts, sessions, verification records, contact messages, sent email or analytics records. The current profile has no self-service account deletion control.
- The database or app hosting provider and data location, and the email proxy's downstream delivery provider and retention practices.
- Whether analytics is enabled on the live deployment, the platform's exact data use and retention details, and whether a separate consent configuration applies.
- Whether authentication requests populate the schema's optional IP address and user-agent session fields, and the session expiry details.
- A formal process for privacy requests and an effective or review date.